Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x6jw-w885-qwpc

Опубликовано: 15 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to limit the number of @-mentions processed per message, allowing an authenticated attacker to crash the client applications of other users via large, crafted messages.

Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to limit the number of @-mentions processed per message, allowing an authenticated attacker to crash the client applications of other users via large, crafted messages.

EPSS

Процентиль: 33%
0.00132
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-400
CWE-770

Связанные уязвимости

CVSS3: 4.3
nvd
почти 2 года назад

Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to limit the number of @-mentions processed per message, allowing an authenticated attacker to crash the client applications of other users via large, crafted messages.

CVSS3: 4.3
debian
почти 2 года назад

Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x bef ...

EPSS

Процентиль: 33%
0.00132
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-400
CWE-770